First published: Fri Apr 07 2023(Updated: )
Apache Software Foundation's Apache Airflow Drill Provider before 2.3.2 is vulnerable to improper input validation because the host passed in drill connection is not sanitized.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Apache-airflow-providers-apache-drill | <2.3.2 | |
pip/apache-airflow-providers-apache-drill | <2.3.2 | 2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Apache Airflow Drill Provider vulnerability is CVE-2023-28707.
The severity of CVE-2023-28707 vulnerability is high with a severity value of 7.5.
The Apache Airflow Drill Provider version before 2.3.2 is affected by CVE-2023-28707 vulnerability.
The CWE ID for CVE-2023-28707 vulnerability is CWE-20.
To fix CVE-2023-28707 vulnerability in Apache Airflow Drill Provider, update to version 2.3.2 or later.